Fortinet published eight security advisories on August 12, 2026, and the one to read first affects FortiWeb, the company's web application firewall. Tracked as CVE-2026-26035 and scored 8.8, it lets a remote attacker with no credentials log into the FortiWeb GUI or CLI using a random username and password.
The important caveat is configuration. Fortinet says the flaw only applies where remote RADIUS administrator authentication has been set up with specific, non default settings, namely the Wildcard option on a remote type admin account. The company found the bug in its own audit rather than in the wild. Affected builds are FortiWeb 8.0.0 through 8.0.2 (fixed in 8.0.3), 7.6.0 through 7.6.6 (fixed in 7.6.7), 7.4.0 through 7.4.11 (fixed in 7.4.12) and 7.2.0 through 7.2.12 (fixed in 7.2.13). If you cannot patch straight away, the Fortinet advisory says to open the remote type administrator account under System, Administrators and disable Wildcard.
The rest of the batch
The other seven, in descending order of severity, are all rated Medium or High and none of them is listed as known exploited:
- CVE-2026-70465 (7.3), FortiClient for Windows. A missing size check in a kernel driver means an attacker positioned to alter or craft DNS responses to the target can execute code via malicious packets. Versions 7.4.0 through 7.4.3 move to 7.4.4, and 7.2.0 through 7.2.11 to 7.2.12; the 8.0 branch is not affected. Reported by Nir Chako of Pentera. The workaround is to disable application based filtering in the FortiClient EMS VPN profile.
- CVE-2026-70468 (7.3), FortiManager and FortiManager Cloud. With a specific CLI option set, an unauthenticated attacker holding a valid certificate can impersonate any FortiGate the FortiManager manages, using crafted FGFM requests. Fixes land in 7.6.2, 7.4.6 and 7.2.10, and the advisory gives a config workaround of setting fgfm-peercert-withoutsn to disable.
- CVE-2026-49975 (5.8), inherited from Apache. A memory allocation flaw in Apache HTTP Server's mod_http, affecting 2.4.17 through 2.4.67, allows denial of service. Fortinet lists fixes or upcoming fixes for FortiPAM, FortiProxy and FortiSwitchManager, says FortiOS, FortiSASE and FortiPresence are still under investigation, and confirms FortiDDoS, FortiADC, FortiWebManager and FortiSOAR are not impacted.
- CVE-2026-71407 (5.1), FortiOS explicit proxy. A stack based buffer overflow in the WAD daemon, exploitable only where the explicit proxy runs Kerberos authentication with SOCKS enabled, and only by an attacker who can already defeat stack protection and ASLR. FortiOS 7.6.1 through 7.6.6 move to 7.6.7. Reported by the UK's National Cyber Security Centre.
- CVE-2026-71408 (5.0), FortiOS web interface. An unauthenticated slow HTTP denial of service against the admin GUI, which Fortinet describes as a regression of an issue it fixed in 2019. Reported by Iván Domínguez of Zerolynx.
- CVE-2026-70466 (4.8), FortiWeb. An incomplete list of disallowed inputs lets an unauthenticated attacker slip crafted requests past WAF policies. Reported by Rui Xi (@Cycloctane) of Beijing University of Posts and Telecommunications.
- CVE-2026-70467 (3.4), FortiSIEM. An authenticated user can make the appliance issue HTTP requests on their behalf, a server side request forgery. Reported by the researcher khalooda0x, Khaled ibn Al-Walid.
What you should do
Patch order should follow exposure rather than score alone. The FortiWeb admin bypass matters most to anyone running remote RADIUS administrator accounts, and it is worth checking whether the Wildcard option is on before assuming you are out of scope. The FortiManager issue is the quietest of the serious ones and potentially the most damaging, since impersonating a managed firewall puts an attacker inside a trust relationship rather than at the perimeter. For the two FortiWeb and FortiOS proxy issues, Fortinet has shipped virtual patches (FG-VD-10009598.0day in FMWP database update 26.071 and FG-VD-10009617.0day in update 26.073) for customers who need cover before a version upgrade.
None of these is under attack today, but Fortinet appliances rarely stay quiet for long. CISA added a FortiOS flaw to its Known Exploited Vulnerabilities catalog in July, and attackers were hijacking FortiSandbox analysis servers through unauthenticated API flaws in June. Edge devices get scanned within days of an advisory, so treat the published version tables as a deadline.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.